#VU66683 Improper access control in Crypto Application Server (CAS)

 

#VU66683 Improper access control in Crypto Application Server (CAS)

Published: August 22, 2022


Vulnerability identifier: #VU66683
Vulnerability risk: Critical
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:A/U:Red
CVE-ID: N/A
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild
Vulnerable software:
Crypto Application Server (CAS)
Software vendor:
General Bytes

Description

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to improper access restrictions to the default installation page. A remote attacker can connect to the default installation URL and create an administrative user account.

Note, the vulnerability is being active exploited in the wild.


Remediation

Install updates from vendor's website.

External links